what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

webevent.txt

webevent.txt
Posted Oct 21, 2000

Webevent v3.3.3 (webevent.pl) is an online calendar which contains a remote cgi vulnerability which allows administrative access.

tags | exploit, remote, cgi
SHA-256 | 5496ce9dcc8d0910d984fc7e479e1a67727682f51767ceae31adf5e834118d53

webevent.txt

Change Mirror Download
To whom it may concern,

I found what seems to be a bug in a program called webevent
(www.webevent.com). Webevent is a calander program that allows multiple
users to post to, and read the calander. The bug comes in from the fact that
you still have access to the perl file that is run when the administrator
runs the program for the first time. Once you run this perl file, it asks
you to enter in the admin info, e.g name, email, and....password. I've
tested version we3.3.3, i found this version running at www.eosmith.org
(you can access firsttime at
www.eosmith.org/scripts/we3.3.3/webevent.pl?cmd=firsttime (this is used to
change the admin info and pass) and
www.eosmith.org/scripts/we3.3.3/webevent.pl?cmd=login to login. Perhaps
earlier versions have the same problem. One way around this is to simply
delete the firsttime.pl file after you configure webevent. I also wonder if
this is a problem with whether you are using the .cgi extension or .pl
extension....also, since you have access to write events once you get admin,
i am looking into how you write to the server when you create and
submitevents.
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.

Share information about yourself, create your own public profile at
http://profiles.msn.com.

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    35 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close